Ukuba sengozini ku-vhost-net evumela ukudlula ukuzehlukanisa kumasistimu asuselwe ku-QEMU-KVM

Kwembulwa ulwazi mayelana ubuthakathaka (I-CVE-2019-14835), okukuvumela ukuthi weqe isistimu yesivakashi ku-KVM (qemu-kvm) futhi usebenzise ikhodi yakho eceleni kwendawo yokusingatha kumongo we-Linux kernel. Ukuba sengozini kuqanjwe ngekhodi ethi V-gHost. Inkinga ivumela isistimu yesivakashi ukuthi idale izimo zokuchichima kwebhafa kumojuli ye-vhost-net kernel (i-network backend ye-virtio), esetshenziswa ohlangothini lwendawo yomsingathi. Ukuhlasela kungase kwenziwe umhlaseli onokufinyelela okukhethekile kusistimu yesivakashi phakathi nomsebenzi wokufuduka komshini obonakalayo.

Ukulungisa Inkinga kufakiwe kufakwe ku-Linux 5.3 kernel. Njengezindlela zokuvimbela ubungozi, ungakhubaza ukufuduka bukhoma kwezinhlelo zezihambeli noma ukhubaze imojuli ye-vhost-net (engeza β€œuhlu olumnyama lwe-vhost-net” ku-/etc/modprobe.d/blacklist.conf). Inkinga ibonakala iqala ku-Linux kernel 2.6.34. Ukuba sengozini kulungisiwe Ubuntu ΠΈ Fedora, kodwa kusalokhu kungalungiswanga Debian, I-Arch Linux, SUSE ΠΈ RHEL.

Source: opennet.ru

Engeza amazwana